BridgeLink plugin

SSL Settings

SSL/TLS encryption for your BridgeLink connectors.

v3.2.0 BridgeLink 26.3–26.6

Why it matters

Protect data in transit.

Healthcare data, including patient health information, is among the most sensitive data your organization handles, and regulations like HIPAA require it to be protected whenever it moves across a network. Without encryption, messages between systems can be intercepted. The SSL Settings plugin closes that gap by encrypting traffic at the connector level, both when BridgeLink receives messages and when it sends them.

Capabilities

What it does:

Encrypted connectors

Add SSL/TLS to HTTP, TCP, and Web Service listeners and senders, so data is encrypted in transit.

Protect PHI

Keep messages from being intercepted on the network, helping protect patient health information.

Compliance support

Meet requirements like HIPAA that mandate protecting data whenever it is transmitted over a network.

Release highlights

What's new.

New features

  • Validation Mode selector: choose PKIX Chain, Pinned Leaf, or Trust All per connector.
  • Certificate revocation checking: OCSP, CRL, or OCSP with CRL fallback (opt-in).
  • Expiration notifications: a daily background check warns 30 days before a certificate expires (configurable).
  • Subject/SAN policy filter: regex rules to restrict inbound client certificates on listeners.

Security updates

  • Private-key export now requires the keystore password.
  • Lockout protection: three failed attempts trigger a 60-second lockout.
  • Audit logging of all certificate export attempts.

Improvements

  • TLS 1.1 disabled by default: new channels use TLS 1.2 and 1.3, with legacy still available behind a warning.
  • Expanded key formats: auto-detects PKCS#8, PKCS#12 (.p12 / .pfx), and DER on import.
  • JKS (Java KeyStore) export format.

How it works

Get started in minutes.

  1. 1

    Install or enable the plugin

    It ships pre-installed on BridgeLink Standard, Enterprise, and the AWS Marketplace 'Advanced with SSL' editions, or installs from the Extensions screen in a few clicks.

  2. 2

    Manage your certificates

    Use the built-in Certificate Manager to create a self-signed certificate or import one from a Certificate Authority, and trust the external systems you connect to.

  3. 3

    Secure your connectors

    Turn on SSL/TLS for your HTTP, TCP, and Web Service connectors, on both the listeners that receive messages and the senders that deliver them.

  4. 4

    Stay ahead of expirations

    Enable certificate monitoring to get email alerts a set number of days before any certificate expires, so connections never fail unexpectedly.

Requirements

What you'll need:

  • BridgeLink with administrator access
  • A TLS certificate: create a self-signed one or import from a Certificate Authority
  • Connectors to secure: HTTP, TCP, or Web Service (listeners and senders)
  • Key store format: JKS, JCEKS, or PKCS12

FAQ

Frequently asked questions.

Which connectors can I secure?

HTTP, TCP, and Web Service connectors, on both the listener (receiving) and sender (sending) sides.

Do I need to buy a certificate?

No. You can create a self-signed certificate in the built-in Certificate Manager, or import one from a Certificate Authority if you prefer.

How does this help with HIPAA compliance?

It encrypts messages in transit, which helps meet requirements like HIPAA that mandate protecting data whenever it is transmitted over a network.

What certificate formats are supported?

Key stores in JKS, JCEKS, and PKCS12, plus imports from keystore files or separate private key and certificate files in PEM, PKCS8, or DER.

What happens when a certificate is about to expire?

Enable certificate monitoring to receive email alerts a configurable number of days before expiration, so SSL connections never fail unexpectedly.

Availability

Pre-installed on several Innovar Healthcare editions, including BridgeLink Standard Edition and the AWS Marketplace 'Advanced with SSL' packages.

Add SSL Settings to BridgeLink.

Talk to us about your deployment, or read the full user guide to get started.